CVE-2025-25288
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 14, 2025
CWE ID 1333
Summary
CVE-2025-25288 is a vulnerability affecting the `@octokit/plugin-paginate-rest` package, used for paginating responses from the Octokit REST API. Versions prior to 11.4.1 are susceptible to a ReDoS (Recursive Denial of Service) attack. A malicious `link` parameter in the `headers` section of the `request` can be exploited by a specially crafted `octokit` instance, leading to excessive resource consumption and potential denial of service. The vulnerability has been addressed in version 11.4.1, which includes a fix for the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.